started · updated
Japan: Multiple companies report unauthorized access and data leaks
Multiple Japanese organizations have reported unauthorized access and potential data leaks resulting from various cybersecurity vulnerabilities.
Kaga Solnet confirmed that approximately 165,587 customers of its Academico Navi site had personal information leaked, including names, addresses, and contact details, due to an attack occurring between December 2021 and April 2026. The company is rebuilding its system and plans to resume service in late October 2026.
Kyodo News reported that approximately 6,000 records related to staff and business partners, such as names and email addresses, may have been viewed after unauthorized use of employee accounts. NTT Smart Connect disclosed unauthorized access to its Smile Server rental service, leading to the suspension of certain facilities to prevent further damage.
Gakken Medical Support identified unauthorized access to 78 websites managed by its web production division, targeting WordPress vulnerabilities to create accounts or change passwords. Additionally, Kankyo Kiki reported a potential leak of personal and credit card information for 15 customers on its Mushitaiji.com site due to a vulnerability in an Amazon Pay plugin.
Entities
Gakken Medical Support · Kaga Solnet · Kankyo Kiki · Kyodo News · NTT Smart Connect